MicrosoftDocs / sysinternals

Content for sysinternals.com
http://sysinternals.com
Creative Commons Attribution 4.0 International
473 stars 259 forks source link

It's not possible to unload the procmon/Process Monitor driver without a reboot #302

Closed ganego closed 4 years ago

ganego commented 4 years ago

When starting Process Monitor, the program loads a driver C:\Windows\system32\Drivers\PROCMON24.SYS. Even after closing the program, the driver is still active.
This will be a problem when running software that requires the BattleEye anti-cheat software, as BattleEye cannot check this driver or unload it.

See: https://superuser.com/questions/1346125/how-can-i-unload-the-process-monitor-driver-without-restarting

When using Windows 10, even a "normal" (quick) reboot won't help and you have to manually enforce a "real" reboot.

foxmsft commented 4 years ago

Hey, thanks for the report. Keep in mind that this repo is only dedicated to documentation.

Please head over to the Sysinternals TechNet forum for more support, both community-driven and from the team, as that place is the recommended contact for troubleshooting and bug reports. I have created a question there for this issue, feel free to reply there so that you get notifications from new activity.

I'll close this issue here.

karl-police commented 2 months ago

Hey, thanks for the report. Keep in mind that this repo is only dedicated to documentation. Please head over to the Sysinternals TechNet forum for more support, both community-driven and from the team, as that place is the recommended contact for troubleshooting and bug reports. I have created a question there for this issue, feel free to reply there so that you get notifications from new activity. I'll close this issue here.

NO, help us

thanks :)